Post

2026-05

2026-05

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - May 2026


πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)PreviewBring Azure Container Apps environments into Defender for Cloud’s Serverless Containers Posture experience for unified container posture management.
🟒Confidential Compute support on Azure Container AppsGARun regulated/sensitive containerized workloads with stronger in-memory data protection and compliance controls.
🟒Monitor HTTP traffic in Azure Container AppsGANew ContainerAppHTTPLogs diagnostic setting category exposes detailed HTTP access logs for high-volume request data via Azure Monitor.
🟒OpenTelemetry destinations (New Relic, Dynatrace, Elastic)GAExpanded OTel endpoint options for third-party observability platforms.
🟒Override Scale Rules in Azure Functions on Azure Container AppsGANew allowScalingRuleOverride property lets customers override platform-managed KEDA scale rules.
🟑Azure Container Apps SandboxesPreviewHyper-V isolated sandboxes for running untrusted code safely with pre-warmed pools and MCP integration.
🟑Azure Container Apps ExpressPreviewStreamlined container deployment without environment setup; sub-second startup and scale-to-zero by default.
πŸ”΅Running production AI agents on Azure Container AppsUpdateFoundry Agent Service uses ACA as runtime for long-running, event-driven AI agents with serverless scaling and isolation.
πŸ”΅Custom scaling control with KEDA rule overridesUpdateOverride platform-generated KEDA rules for full control over scaling thresholds, event sources, and multi-signal scenarios.
πŸ”΅Modernizing legacy applications to ACAUpdateGitHub Copilot App Modernization reduces legacy-to-ACA migration effort from weeks to hours with managed identity and Key Vault integration.
πŸ”΅Safely executing AI-generated code with Dynamic SessionsUpdateHyper-V isolated sandboxes, pre-warmed pools, and MCP integration for secure execution of untrusted/AI-generated code.

β›΅ AKS

IndicatorFeatureTypeDescription
πŸ”΄CVE-2026-31431 β€œCopy Fail” - Local Privilege Escalation in Linux kernel algif_aeadSecurityCVSS 7.8 HIGH LPE vulnerability requiring code execution on the node; affects AKS nodes using the affected kernel module.
πŸ”΄Kubernetes patch versions 1.35.4, 1.34.7, 1.33.11 (Go 1.25.9)SecurityFixes CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289.
πŸ”΄Kubernetes patch versions 1.35.5, 1.34.8, 1.33.12SecurityAdditional patch releases with security fixes.
πŸ”΄Azure Policy add-on v1.15.5-1 patches multiple CVEsSecurityPatches CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2026-32280, CVE-2025-68121, CVE-2025-61726, CVE-2025-61728, CVE-2026-32281, CVE-2026-32283.
πŸ”΄Azure Blob CSI driver updated with latest security patchesSecurityAzure Blob CSI driver v1.26.12 (AKS 1.32+) and v1.27.5 (AKS 1.34+).
πŸ”΄ACNS DNS proxy security patch updatesSecurityDNS proxy v1.18.9-260520 includes security patch updates addressing CVEs.
πŸ”΄Defender for Containers sensor v0.9.53 / v0.8.50 with malware scanningSecurityMalware scanning as new optional capability; blocking support for GA Drift Detection.
πŸ”΄Defender for Containers sensor v0.10 on AKS 1.36SecurityNew sensor version with enhanced capabilities.
⚫Istio add-on revision asm-1-27 deprecatedDeprecationUpgrade to revision 1.28 or later following the Istio add-on upgrade guide.
⚫Windows Server Annual Channel for Containers retired (May 15, 2026)DeprecationLast image 5B produced; migrate to LTSC by May 15, 2027.
⚫Windows Server 2019 retired (March 1, 2026)DeprecationNo new node images or security patches; unsupported; removal April 1, 2027.
⚫Flatcar Container Linux support ends June 8, 2026DeprecationMigrate to Azure Container Linux; node image removal September 8, 2026.
🟒Windows Server 2025 generally availableGANo feature flag required; supported on Kubernetes 1.32+ with CLI 2.87.0+.
🟒Azure Container Linux GA on AKS v1.34+GAACL node pools available; in-place OS SKU migration supported.
🟒Azure Policy add-on generates ValidatingAdmissionPoliciesGACEL-based policies enforced inside API server for minimal latency with fail-closed enforcement.
🟒AKS end of support notificationsGAAutomatic notifications via Azure Resource Graph and Event Grid when cluster version approaches/ passes end of support.
🟑Azure Linux 3.0 confidential VM preview (Fairfax regions)PreviewRegister AzureLinuxCVMPreview feature flag to enable.
🟑In-place node pool resizePreviewResize VMSS node pool VM size via az aks nodepool update --node-vm-size without migration.
🟑Automatic Pod Disruption Budget managementPreviewAKS auto-creates PDBs and scales replicas to unblock node drain during upgrades.
πŸ”΅AKS-2026-0004: Container Insights nodes/proxy RCE risk on K8s < 1.33UpdateContainer Insights add-on uses nodes/proxy permission on clusters < v1.33; upgrade to v1.33+ for fine-grained nodes/pods subresource.
πŸ”΅Kubernetes 1.36 Preview rolling outUpdateNew version being rolled out across regions.
πŸ”΅LocalDNS auto-enabled on node pools running K8s 1.36+UpdateAutomatic enablement with exclusion options for pre-configured or BYO CNI clusters.
πŸ”΅NAP Standard SKU defaults to LocalDNS mode Preferred on K8s 1.36+UpdateImproved DNS resolution performance and resilience.
πŸ”΅Application routing Gateway API access logs to stdoutUpdateManaged Istio configuration now writes access logs to stdout by default.
πŸ”΅Application routing DNS/TLS integration with Gateway APIUpdateTLS via Key Vault CSI driver; DNS A records via ExternalDNS CRDs.
πŸ”΅Migration to block/none outbound types from managedNATGatewayV2UpdateSupports network-isolated cluster scenarios.
πŸ”΅Pod CIDR validation for kubenet and Azure CNI OverlayUpdateBlocks overlapping with reserved ranges 172.30.0.0/16 and 172.31.0.0/16.
πŸ”΅Calico NPM/Azure NPM blocked on K8s < 1.30UpdateInstall/uninstall operations rejected at API level; existing clusters unaffected.
πŸ”΅AGIC add-on blocked from using aks-appgateway subnetUpdateSubnet reserved for Application Gateway for Containers.
πŸ”΅Managed system node pools GA for AKS AutomaticUpdateMultiple security restrictions: blocks SSH keys, externalIPs, port-forward on system pool, kube-system secret access, mutating admission resources.
πŸ”΅Deployment safeguards Enforce mode allows /var/log and /hostfs read-onlyUpdateSupports log exporter scenarios on Automatic clusters.
πŸ”΅Istio webhook fix for v1beta1 Gateway resourcesUpdateFixed β€œUnknown gvk” error from admission webhook.
πŸ”΅Multiple Standard Load Balancers rebalance fix for orphaned nodesUpdateOrphaned nodes now included during rebalancing.
πŸ”΅Cluster create/update failure on Karpenter/KEDA silent install failureUpdateOperation now fails with descriptive error instead of silent success.
πŸ”΅Azure Disk CSI driver upgradesUpdatev1.33.10 (AKS 1.33/1.34), v1.34.4 (AKS 1.35).
πŸ”΅Azure File CSI driver upgradesUpdatev1.33.10 (AKS 1.33), v1.34.6 (AKS 1.34), v1.35.3 (AKS 1.35).
πŸ”΅Cloud Provider Azure v1.36.0Updatecloud-controller-manager and cloud-node-manager updated; health-probe-proxy updated.
πŸ”΅Azure CNI Powered by Cilium updatesUpdateCilium v1.19.3 (K8s 1.36+), v1.18.9 (K8s 1.34).
πŸ”΅Azure Monitor Prometheus add-on v7.0.0UpdateMay release incorporated.
πŸ”΅NAP Karpenter provider v1.12.1UpdateUpdated Karpenter provider.
πŸ”΅AKS Windows and Linux node image updatesUpdateMultiple VHD updates for Windows Server 2022/2025/23H2, Azure Linux v3.0, Ubuntu 22.04/24.04.

πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
🟒Workspace replication supports private links during failoverGARemoves previous limitation blocking private endpoint customers in BCDR scenarios.

☁️ Microsoft Defender Cloud Apps

IndicatorFeatureTypeDescription
🟑Disable informational alerts for unsanctioned app accessPreviewNew toggle suppresses informational alerts while keeping blocking enforcement active.

🧠 Microsoft Copilot Studio

IndicatorFeatureTypeDescription
🟒Computer use for agentsGAAgents can automate web and desktop apps by controlling browsers and desktop applications.
🟒Prompt node in agent flowsGASingle AI call with dynamic content and model selection for translation, extraction, etc.
🟒Microsoft 365 Copilot nodeGASend prompts to M365 Copilot or specific agents for research and audit drafting.
🟒Consent-based recording on voice agentsGAConfigurable compliance behavior and retention settings for call recording consent.
🟒Agent inventory schemaGADiscover and audit all Copilot Studio agents via admin center, API, or Azure Resource Graph.
🟑Agent readiness and issue status pagePreviewConsolidated status page with publishing errors, runtime issues, and configuration blocks.
🟒Asynchronous responses for agent flowsGALong-running processes can exceed the two-minute limit.
🟑Microsoft Entra agent identities per agentPreviewScope connector permissions, Conditional Access, and DLP governance to individual agents.
🟑Computer use standalone toolsPreviewModular, reusable UI automation with built-in governance and observability.
🟑Mistral Medium 3.5 as primary AI modelPreviewExperimental option alongside Anthropic, xAI, and other providers.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟒Sensor v0.10.5 - Runtime antimalware detection and blocking GAGAGeneral availability of runtime antimalware detection and blocking for containers.
🟒Sensor v0.10.5 - Bottlerocket OS support GAGAGeneral availability of Bottlerocket OS support.
🟒Sensor v0.10.5 - Nexus Baremetal cluster compatibilityGAImproved compatibility with Nexus Baremetal clusters.
πŸ”΄Sensor v0.10.5 - Go dependency security fixesSecurityUpgraded Go and related dependencies to address security vulnerabilities.
🟒Sensor v0.9.58 - Bottlerocket OS support GAGAGeneral availability of Bottlerocket OS support.
🟒Sensor v0.9.58 - Nexus Baremetal cluster compatibilityGAImproved compatibility with Nexus Baremetal clusters.
πŸ”΄Sensor v0.9.58 - Go dependency security fixesSecurityUpgraded Go and related dependencies to address security vulnerabilities.
🟒Sensor v0.8.51 - Nexus Baremetal cluster compatibilityGAImproved compatibility with Nexus Baremetal clusters.
πŸ”΄Sensor v0.8.51 - Go dependency security fixesSecurityUpgraded Go and related dependencies to address security vulnerabilities.

🚨 Microsoft Defender XSPM (Exposure Management)

IndicatorFeatureTypeDescription
πŸ”΅Senior Executive User Workstation classificationUpdateNew predefined Device classification rule for critical assets list; relies on Senior Executive identity classifications.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟑Private clusters protection for gated deployment, binary drift, malware detectionPreviewDefender sensor extends to private cluster scenarios for container protection.
🟑Malware detection for EKS and GKE nodesPreviewKubernetes node malware coverage expanded beyond AKS to multicloud environments.
🟒On-demand malware scanning of Azure FilesGAExtend on-demand scanning to Azure Storage accounts containing blobs and files.
🟒Defender for Open-Source Relational Databases on AWS RDS (GA June 1)GABilling begins June 1, 2026; auto-transition from preview; opt-out available.
🟑Cloud security reporting in Microsoft Defender portalPreviewCreate, customize, and share CNAPP Executive Summary and Cloud Posture reports with PDF export.
🟑Scanning support for Docker Hardened container imagesPreviewVulnerability scanner extends to Docker Hardened images; may increase bill.
πŸ”΅Defender Experts for Servers as managed XDR optionUpdatePartnered with Microsoft Defender Experts for managed XDR on server workloads across Azure, AWS, GCP, on-prem.
🟑SQL VA Express Configuration for Azure SQL Managed Instance and SynapsePreviewMicrosoft-managed storage for vulnerability baselines; no customer-managed storage account required.
πŸ”΅Updated Helm installation for Defender for Containers sensorUpdateDirect Helm chart deployment instead of installation scripts for AKS, EKS, GKE.
⚫Deprecation of legacy grouped recommendations (removal July 31, 2026)DeprecationIndividual recommendations now GA; grouped types tagged β€œSet for deprecation” and removed July 31.
πŸ”΅Daily score calculation enhancement for risk-based Cloud secure scoreUpdateEnd-of-day snapshots instead of averaged values; historical values recalculated.
🟑Defender for Cloud integration into Defender portalPreviewUnified cloud security dashboard, posture management, risk-based secure score, and centralized asset inventory.
πŸ”΄Defender for Cloud and GitHub Advanced Security integrationSecurityGA integration connecting runtime security signals with code-level vulnerability management; bidirectional sync, AI-powered remediation, security campaigns.

πŸ›‘οΈ Microsoft Defender Unified SecOps

IndicatorFeatureTypeDescription
πŸ”΅No specific May 2026 updates listedUpdatePage references general unified SecOps capabilities.

🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
πŸ”΅Defender Experts for Servers as standalone offeringsUpdateManaged XDR and threat hunting for on-premises and multicloud servers now standalone (previously add-ons to XDR).
🟑Automatic attack disruption - device isolationPreviewHigh-confidence incident analysis can isolate compromised devices from the network; time-limited, scoped, releasable.
πŸ”΅Advanced hunting Take action wizard - allow/block TLDs and attachment hashesUpdateAllow or block top-level domains and file attachment hashes in emails based on query results.
🟒Hunting graph identity-focused predefined scenariosGANew scenarios for Kerberoast, AS-REP roast, domain compromise, OAuth app risks, guest user access.
🟑Defender Chat experiencePreviewOpen prompt chat assistant built into Defender for SOC analysts to investigate threats in plain language.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟒Defender endpoint security solution for Windows 7 SP1 and Windows Server 2008 R2 SP1GAAdvanced protection for legacy Windows devices via Defender deployment tool.
🟑Enhanced exposure score in Defender Vulnerability ManagementPreviewNew model incorporating EPSS exploit prediction data and asset context (internet-facing, criticality).
🟑Schedule antivirus scans on LinuxPreviewConfigure hourly quick, interval-based quick, and weekly full scans with low-priority and idle-time options.
🟑Automatic device isolation (automatic attack disruption)PreviewTime-limited network isolation blocking attacker communication while keeping security services connected.
🟒Custom data collectionGARule-based telemetry collection beyond defaults; max event limit increased from 25,000 to 75,000 per device per 24h.
🟒Configure offline security intelligence update settings for Linux from portalsGAConfigure offline update settings for Linux from Defender and Intune portals.
🟑Selective Response ActionsPreviewTailor high-impact security operations on Tier-0 systems and high-value assets during onboarding.
🟒Windows Defender Antivirus Platform 4.18.26040.7 / Engine 1.1.26040.8GASee endpoint-release-notes for details.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΅Windows Antivirus Platform 4.18.26050.15 / Engine 1.1.26050.11UpdateMay 2026 release with security intelligence 1.453.4.0; support phase: Security and Critical Updates.
πŸ”΅Fixed remote-share file scans missing detections via symlinkUpdateFile scans through symlinks now correctly detect threats.
πŸ”΅Fixed mpcmdrun -scan non-ASCII character display in localized pathsUpdateOutput no longer displays incorrect characters in localized paths and threat names.
πŸ”΅Fixed network protection watchdog timers silently not firingUpdateWatchdog timers now correctly fire instead of failing silently.

macOS

IndicatorFeatureTypeDescription
πŸ”΅macOS 15.0.1 minimum support; macOS 11 (Big Sur) and 12 (Monterey) no longer supportedUpdateMinimum supported version updated; older macOS versions end of life.

Linux

IndicatorFeatureTypeDescription
πŸ”΅Regular monthly updates with security fixesUpdateSecurity fixes included as part of monthly releases; see Microsoft Security Update Guide for details.

🏒 Microsoft Entra ID

IndicatorFeatureTypeDescription
🟑Soft-delete for Microsoft Entra Device objectsPreviewRecoverable device deletion with defined retention period; supports all join types.
πŸ”΅NetBiosName resolution test reclassified to informationalUpdateNo longer generates alerts; reduces noise in Connect Health alert feed.
πŸ”΅Enhanced admin authorization for Entra Connect Sync config changesUpdateInteractive admin sign-in required for sync configuration changes via wizard and PowerShell.
πŸ”΅Workload identity-based authentication for SAP SuccessFactors provisioningPreviewShort-lived tokens replace static credentials; prepare for SAP basic auth deprecation by November 2026.
🟑Sensitivity labels for Microsoft Entra security groupsPreviewApply Purview sensitivity labels to govern guest access settings on security groups.
🟒Account Discovery for connected applicationsGAVisibility into all accounts including orphan accounts via provisioning discovery reports.
🟒Cross tenant group synchronizationGASynchronize security groups across tenants with centralized membership management.
πŸ”΅Modernized My Account pages (Devices, Personal Info, Organizations)UpdateGA by end of June 2026; BitLocker keys more prominent; improved leave-organization flow.
🟒Passkeys (FIDO2) support in Registration CampaignsGAConfigure campaigns to nudge users to register passkeys during sign-in.
πŸ”΅Automate user attribute updates in Lifecycle WorkflowsPreviewSet or clear attribute values directly within workflows with auditable governance.
🟒System-preferred authentication extended to first-factorGAUsers with phishing-resistant credentials may skip password entry entirely.
🟒High Scale Compatibility mode for Entra External IDGAMigrate from Azure AD B2C while preserving existing user directory for large-scale migrations.
πŸ”΅Expanded passkey (FIDO2) policy storageUpdateDedicated 20-KB allocation for passkey policy; max profiles increased from 3 to 10.
🟑Azure Role assignments governed via Entitlement ManagementPreviewGovern Azure role assignments at MG/Sub/RG level through access packages with JIT and least privilege.
🟒Manage Agent ID sponsorship lifecycle with Lifecycle WorkflowsGAAutomatic sponsor transfer on departure; notification workflows for sponsorship changes.

πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟑Eventstream Business Events publisherPreviewFilter, aggregate, threshold, and emit governed business signals from Eventstream canvas with no code.
🟑Service principal support for Fabric data agentsPreviewSPN authentication for data agent API; custom apps and Foundry agents use application identity instead of delegated user tokens.

πŸ—οΈ Microsoft Foundry

IndicatorFeatureTypeDescription
🟒Trace-based evaluation for external and hosted agentsGAGrade production traces from Foundry, GCP, AWS, or any framework without hand-curated datasets.
🟒Grok 4.3 model availabilityGAxAI’s latest model for advanced agentic and domain-specific workloads.
🟒DeepSeek V4 model familyGANewest DeepSeek model family expands open-model choice in catalog.
🟒GPT-5 Reinforcement Fine-Tuning (Gated GA)GAEnterprise-ready compliance and SLA coverage for RFT.
🟒Managed VNETGAMicrosoft-managed network isolation reaches general availability.
🟒Project-level cost attributionGASee LLM costs by project for budget tracking and governance.
🟒Content Understanding improvements (Read and Layout analyzers GA)GARead and layout analyzers reach GA alongside Logic App connector and Foundry NextGen integration.
πŸ”΅MagenticBrain, Fara1.5-9B, MagenticLite on-device agent projectsUpdateMicrosoft Research ships three on-device agent projects for reasoning, UI automation, and local workflows.
πŸ”΅SocialReasoning-Bench + STATE-Bench benchmarksUpdateOpen-source benchmarks for agent negotiation, coordination, and memory quality.
πŸ”΅Evaluation tooling updatesUpdateSkill evaluation, workflow evaluation UX improvements, alignment across VS Code and portal.
πŸ”΅Foundry Local 1.1 + 1.2UpdateLive audio transcription, text embeddings, Qwen 3.5 Vision, multilingual ASR, Linux ARM64, ONNX Runtime 1.26.
πŸ”΅azure-ai-projects SDK 2.2.0UpdatePreview skills and toolboxes; external agent definitions, model weight registry, routines, optimization jobs.

πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
πŸ”΅Sensor v3.x supports all identity roles on domain controllersUpdateSupports Microsoft Entra Connect, AD FS, and AD CS identity roles on domain controllers.
πŸ”΅Increased sensor capacity (1,000 per workspace)UpdateIncreased from previous limit of 350; contact support for more than 1,000.
πŸ”΄New security alerts related to Entra IDSecurity8 new alerts: guest user promoted to member, user created as Global Admin, failed credential abuse, randomized user agent, stolen session cookie (2 alerts), Conditional Access bypass via non-compliant device, suspicious third-party MFA method addition.
πŸ”΅Known limitation: Windows Server 2025 sensor v2.x to v3.x migration not supportedUpdateContinue using v2.x on WS2025 DCs until migration support is available.

πŸ“§ Microsoft Defender Office 365

IndicatorFeatureTypeDescription
πŸ”΅No specific May 2026 feature updates listedPreviewPage references general Defender for Office 365 capabilities and trial availability.

πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
🟒Data security and compliance protections for Microsoft Agent 365GAGA of data security and compliance protections for AI agents.
🟒Standalone data asset data quality scanGAGA of standalone data quality scanning for data assets.
🟒Incremental data quality scanGAGA of incremental data quality scanning.
🟒Configurable data quality thresholdsGAGA of configurable thresholds for data quality rules and assets.
πŸ”΅DLP admin permissions for unmanaged cloud apps in EdgeUpdateAdded Directory Reader, Edge, and Intune admin permissions required for DLP activation.
πŸ”΅DLP Edge browser profile scope clarifiedUpdateUnmanaged app policies apply across all Edge profiles; managed app policies apply only in work profile.
πŸ”΅DeepL and Zapier removed from unmanaged AI app listUpdateRemoved from browser policy supported list.
🟑Block access for specific external domains/users in DLPPreviewNew sub-option for Restrict access action in SharePoint/OneDrive DLP policies.
🟒OCR support in Data Security InvestigationsGAAutomatic OCR processing of image files for AI analysis.
🟒Custom examinations in Data Security InvestigationsGADefine custom prompts for analysis beyond built-in examination areas.
πŸ”΅Large audit search results guidanceUpdateNew guidance for working with results exceeding ~3,000 items.
🟒Data Security Posture Management new version GAGAGuided workflows for proactive risk management; partner solutions and DSPM Agent remain in preview.
🟒Administrative units support in DSPMGAParity with classic DSPM and DSPM for AI versions.
πŸ”΅Inactive tenant processing pause (60+ days)UpdateProcessing paused for M365 data when tenants inactive >60 days; auto-resume on return.
πŸ”΅Anthropic Claude (Enterprise) data connectorPreviewClaude displays alongside other AI apps in Purview with activity explorer support.
🟑Scanner cluster-level feature control from PowerShellPreviewEnable, disable, and configure scanner features via PowerShell.
🟑Custom Reporting for scannerPreviewAdditional columns and tables in scanner database for custom Power BI/SQL reports.
🟑Custom posture reportsPreviewBuild tailored views of information protection and DLP activity.
🟑Manual labeling support for MP4 files in SharePoint/OneDrivePreviewRolling out sensitivity label support for video files.
🟑Apply meeting label to artifacts (recordings, transcripts, notes)PreviewAuto-apply meeting sensitivity label to recordings and notes.
🟑Label policy sync status visibilityPreviewSee sync status of publishing policies on Label policies page.
πŸ”΅Disabling sensitivity labels for SharePoint/OneDrive documentationUpdateUpdated documentation for opt-out behavior after labels enabled.
🟒Policy-level labeling activity for SharePoint/OneDriveGAPer-policy review pages for monitoring daily labeling activity and investigating failures.

πŸ€– Microsoft Security Copilot

IndicatorFeatureTypeDescription
πŸ”΅No specific May 2026 feature updates listedUpdatePage references ongoing improvements; revisit regularly.

πŸ” Microsoft Sentinel

IndicatorFeatureTypeDescription
🟒Generate playbooks using AI (SOAR playbook generator)GAPython-based automation workflows coauthored via conversational AI with Cline coding agent.
πŸ”΅UEBA enhancements: New settings experienceUpdateConsolidated UEBA and Behaviors Settings view from new UEBA tab in Sentinel settings.
πŸ”΅UEBA Okta V2 supportUpdateOktaV2_CL table support alongside Okta_CL for Anomalous Activity and Anomalous MFA Failures detections.
πŸ”΅UEBA GCP anomaly detections (5 new)UpdateNew detections for unusual login behavior, privileged actions, resource deployments, secret/KMS key access, infrastructure usage patterns.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Upgrade AKS clusters to v1.33+ if using Container Insights to eliminate nodes/proxy RCE riskASAPAKS
πŸ”΄Patch AKS nodes against CVE-2026-31431 β€œCopy Fail” (CVSS 7.8 LPE)ASAPAKS
πŸ”΄Apply Kubernetes patch versions 1.35.5/1.34.8/1.33.12 addressing multiple CVEsASAPAKS
πŸ”΄Migrate Windows Server Annual Channel node pools to LTSC before May 15, 2027May 15, 2027AKS
πŸ”΄Migrate Flatcar Container Linux node pools to Azure Container Linux before June 8, 2026June 8, 2026AKS
🟑Plan migration of SAP SuccessFactors provisioning from basic auth to workload identity-based authNovember 2026Entra ID
🟑Evaluate and adopt Defender for Cloud integration into Defender portal for unified CNAPPOngoingDefender Cloud
🟑Review and tune new Defender for Identity Entra ID security alerts (8 new)OngoingDefender Identity
🟑Enable on-demand malware scanning for Azure Files in Defender for StorageOngoingDefender Cloud
🟒Adopt AKS end of support notifications for proactive version managementOngoingAKS
🟒Evaluate Copilot Studio agent inventory schema for agent governanceOngoingCopilot Studio
🟒Review Purview Data Security Posture Management GA for proactive data risk managementOngoingPurview

Security Architect Observations

  • AKS defense-in-depth upgrades: The nodes/proxy RCE risk (AKS-2026-0004) on pre-1.33 clusters with Container Insights requires immediate upgrade planning. Combined with CVE-2026-31431 β€œCopy Fail” (LPE requiring node code execution), the defense-in-depth posture for AKS clusters must include both Kubernetes version upgrades and kernel patching. The new managed system node pool security restrictions (blocking SSH keys, externalIPs, port-forward, kube-system secret access) on AKS Automatic represent a significant hardening baseline for new clusters.

  • Multicloud container security expansion: Defender for Cloud now extends malware detection to EKS and GKE nodes (preview), Docker Hardened image scanning (preview), and on-demand malware scanning for Azure Files (GA). Security architects should plan for unified container threat detection across AKS, EKS, and GKE with the Defender sensor v0.10+.

  • Entra ID identity security modernization: Multiple changes strengthen the identity plane: system-preferred authentication now covers first-factor (phishing-resistant credentials may skip passwords), passkey policy storage expanded (dedicated 20KB, up to 10 profiles), workload identity-based auth for SAP SuccessFactors (prepare for Nov 2026 basic auth deprecation), and enhanced admin authorization for Entra Connect Sync changes. These collectively reduce reliance on passwords and static credentials.

  • Defender for Cloud + GitHub Advanced Security integration (GA): Runtime-to-code vulnerability correlation with bidirectional sync and AI-powered remediation creates a new DevSecOps feedback loop. Security architects should evaluate this integration for bridging cloud security posture with developer workflows.

  • Deprecation wave in AKS: Four concurrent deprecations (Istio asm-1-27, Windows Server Annual Channel, Windows Server 2019, Flatcar Container Linux) require coordinated migration planning. The Windows Server 2019 and Flatcar timelines are particularly urgent (June/September 2026).

  • Purview DSPM GA with AI data governance: The new DSPM version, Anthropic Claude connector, and Agent 365 protections signal expanding data security posture management to cover AI application data flows. Architects should plan for unified data security across Copilot, Copilot Studio, ChatGPT Enterprise, and Claude.


Security Operations Observations

  • New Defender for Identity Entra ID alerts (8 new): SOC teams must review and tune alerts for stolen session cookies, Conditional Access bypass via non-compliant devices, suspicious MFA method additions, and guest account promotions. These expand identity threat detection beyond on-premises AD to cloud Entra ID attack paths.

  • Automatic attack disruption with device isolation (Preview): SOC workflows should account for time-limited automatic device isolation triggered by high-confidence incidents. Operators can release isolation at any time, but the automated response changes incident response playbooks for containment.

  • Defender Chat experience (Preview): The open prompt chat assistant in Defender enables plain-language investigation. SOC analysts should evaluate this for reducing time-to-investigate without navigating multiple screens or writing complex KQL queries.

  • Sentinel UEBA enhancements: New GCP anomaly detections (5) and Okta V2 support expand UEBA coverage. SOC teams should validate the new UEBA settings experience and ensure Okta V2_CL table is onboarded for anomaly detection coverage.

  • Cloud security reporting in Defender portal (Preview): CNAPP Executive Summary and Cloud Posture reports with PDF export enable streamlined reporting for leadership. SOC teams can use these for regular posture reporting without manual data aggregation.

  • Defender for Cloud daily secure score recalculation: End-of-day snapshots replace averaged values. SOC teams should note that historical values have been recalculated, which may affect trend comparisons. The risk-based Cloud secure score now incorporates individual recommendations.


References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
This post is licensed under CC BY 4.0 by the author.

MS Release Radar

Wiz Release Radar

MS Tech News